EUVD Vulnerability Catalog
EUVD-2026-87102
Severity: CRITICAL
Base Score: 9.3
CVSS Version: 3.1
Vulnerability Description
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): Required
▪
Scope (S): Changed
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): None
Affected Vendors & Systems
Vendor
Zimbra
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
rapid7
EPSS Probability
0
Known Aliases
CVE-2026-93647
GHSA-h5jf-rfhh-rx8c
Published On
2026-09-25
Last Updated
2026-09-26